Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 August 2026

RSS

333 vulnerabilities published on 16 August 2026

Severity:
Edimax EW-7478APC allows remote access disruption
CVE-2026-19959
The Edimax EW-7478APC Wi-Fi router has a security issue that could allow an attacker to disrupt its functionality. This is because the router's software does not properly handle certain input, which c...
8.6
Edimax EW-7478APC allows remote data overflow attacks
CVE-2026-19961
A security flaw in Edimax EW-7478APC's software allows hackers to send malicious data that can cause the system to behave unexpectedly. This can happen remotely, which means it's a risk for anyone usi...
8.6
SiYuan kernel API tokens can be guessed too easily
CVE-2026-73056
Old versions of the SiYuan kernel have a weakness in how they handle API tokens. This makes it easy for an attacker to try many different tokens until they find the right one. To fix this, update to v...
9.3
Perl Net::OAuth::Client Downgrade to OAuth 1.0 Risk
CVE-2026-72887 DEBIAN-CVE-2026-72887
Net::OAuth::Client versions before 0.32 for Perl allow a service provider to quietly change the security level of OAuth 1.0a to OAuth 1.0, which can be exploited by attackers to take control of user a...
9.8
Debian Linux: Unauthenticated Remote Code Execution in Samba
DEBIAN-CVE-2026-19349 CVE-2026-19349
A critical vulnerability in Debian's Samba package allows attackers to execute malicious code on a system without needing a password. This affects any Debian system running Samba, which is used for fi...
9.8
Scriban: Arbitrary CLR Property Writes via Template
CVE-2026-73061 GHSA-7jvp-hj45-2f2m
Scriban, a templating engine, allows templates to write to any public CLR property of objects passed to it, potentially overwriting intended values. This can lead to unexpected behavior in application...
9.9
ARForms Plugin <= 1.8.5: Unauthenticated Attackers Can Delete Files
CVE-2024-13784
The ARForms plugin for WordPress has a security issue that allows unauthenticated attackers to delete files or access sensitive data if another plugin or theme is installed that contains a specific ty...
9.8
Frontend Admin by DynamiApps plugin for WordPress allows unauthorized access to admin accounts
CVE-2026-18432
The Frontend Admin plugin for WordPress has a security flaw that lets attackers gain access to administrator accounts. This can happen when a malicious user submits a specially crafted form on the web...
9.8
ProSolution WP Client Plugin: Unauthenticated File Upload Risk
CVE-2026-16098
The ProSolution WP Client plugin for WordPress has a security issue that allows hackers to upload any file to the website without needing a password. This could allow them to run malicious code on the...
9.8
Tenda AC10 httpd: Remote Authentication Bypass Possible
CVE-2026-19924
A security issue in the Tenda AC10 router's web server could allow an attacker to bypass authentication remotely. This could potentially give the attacker access to the router's settings or other sens...
8.9
Phoca Cart: Unauthenticated SQL Injection via Public Shop Items Page
CVE-2026-74251
The Phoca Cart extension for Joomla has a security issue that allows an attacker to access sensitive information in the database. This can happen when a user visits a public shop items page. To stay s...
9.3
Scriban: Data exposure due to outdated cached accessors
CVE-2026-74790 GHSA-5wr9-m6jw-xx44
If you use Scriban to render templates with sensitive data, a bug can cause previously exposed data to remain accessible even after you tighten security settings. This happens when Scriban reuses a ca...
9.1
WPvivid Backup & Migration < 0.9.131: Uncontrolled Log File Creation
CVE-2026-19725
An attacker can create log files in any directory they choose on a WordPress site using WPvivid Backup & Migration. This can lead to sensitive information being exposed. Update to version 0.9.131 or l...
9.1
Simple JWT Login WordPress Plugin (Google Sign-in) - Unauthorized User Access
CVE-2026-19714
The Simple JWT Login WordPress plugin, used for Google sign-in, allows unauthorized users to access any account, including administrator accounts, if they have the correct email address. This affects ...
9.1
Solace Extra <= 1.6.0 - Unauthorized Site Content Deletion
CVE-2026-18316
The Solace Extra plugin for WordPress has a security issue that allows attackers with a low-level account to delete important site content and settings. This could cause significant data loss and disr...
9.1
ProSolution WP Client plugin for WordPress: Unauthenticated File Deletion
CVE-2026-14524
The ProSolution WP Client plugin for WordPress allows unauthenticated attackers to delete any file on the server, including sensitive files like wp-config.php. This could lead to a complete takeover o...
9.1
Royal Elementor Addons plugin for WordPress exposes internal services to unauthorized access
CVE-2026-17123
A vulnerability in the Royal Elementor Addons plugin for WordPress allows attackers with contributor-level access to make requests to any website, potentially accessing or modifying internal services....
8.8
Query Wrangler plugin for WordPress allows attackers to execute code.
CVE-2026-14498
The Query Wrangler plugin for WordPress has a security flaw that allows an authenticated user to run code on the server. This can happen if the user has a subscriber-level account or higher. To stay s...
8.8
Podlove Podcast Publisher plugin: Arbitrary file deletion on WordPress
CVE-2026-16099
Authenticated users with contributor-level access can delete any files on the server using the Podlove Podcast Publisher plugin for WordPress. This can lead to serious security risks if the wrong file...
8.8
Scriban: Authorized data leaked due to reused template cache
CVE-2026-74791 GHSA-x6m9-38vm-2xhf
Scriban templates can cache authorized content, allowing unauthorized access to sensitive data. This issue affects applications that use Scriban with a pooled TemplateContext and an ITemplateLoader th...
8.3
Scriban: Large Array Insertion Crashes Host Process
CVE-2026-74784 GHSA-24c8-4792-22hx
A malicious template can cause Scriban to crash the host process by inserting a large number of elements into an array, leading to an out-of-memory exception. This can happen even when safety controls...
8.3
stoatchat before 0.15.0 Memory Exhaustion Denial of Service
CVE-2026-73057
The stoatchat software before version 0.15.0 is vulnerable to a denial of service attack. An attacker can exploit this vulnerability by hosting malicious SVG files with large dimensions, which can cau...
8.7
Scriban templates before 6.6.0 can crash the application
CVE-2026-74795 GHSA-wgh7-7m3c-fx25
If you use Scriban templates, an attacker can send a specially crafted template that crashes your application. This can happen even if you're not logged in. To protect yourself, update to Scriban vers...
8.3
Scriban Can Crash When Rendering Circular Data
CVE-2026-74794 GHSA-grr9-747v-xvcp
Scriban's template engine can crash if it encounters circular data, which can happen when user-controlled data is used in templates. This can occur in web applications that map user input to rendering...
8.3
Scriban Template Parsing Can Cause Program Crash
CVE-2026-74792 GHSA-p6q4-fgr8-vx4p
A vulnerability in Scriban template parsing can cause a program crash if it processes a specially crafted input, such as a deeply nested array initializer. This can happen even if the default safety l...
8.3